Junglewise Threat Intelligence

CVE-2017-3421: Oracle One-to-One Fulfillment unauthorized data access in User Interface

CVE-2017-3421 · Severity: high · CVSS 8.2 · Published 2017-01-27

Technologies: Oracle One-To-One Fulfillment. Vendors: Oracle.

Executive brief

Oracle One-to-One Fulfillment is a component of the Oracle E-Business Suite used for managing high-volume personalized communications. A security vulnerability in its user interface allows an attacker to trick a legitimate user into performing actions that compromise the system. If exploited, this could lead to unauthorized access to sensitive business data or the ability to modify and delete records, potentially impacting other integrated Oracle products.

Technical details

This vulnerability affects the User Interface subcomponent of Oracle One-to-One Fulfillment within Oracle E-Business Suite. It is classified as an 'unspecified' vulnerability that is easily exploitable via the HTTP protocol. The attack requires human interaction from a person other than the attacker (UI:R) and results in a Scope change (S:C), suggesting a Cross-Site Scripting (XSS) or similar injection-based flaw. An unauthenticated attacker can gain unauthorized read access to all accessible data and partial update/delete privileges. Affected versions include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle One-to-One Fulfillment 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats